Legal

Privacy Policy

Last updated 10 August 2026

To-Do is a shared checklist app for real-estate work. This page describes everything it stores, who can see it, and how to get it removed. It is short because the app collects very little.

Who runs To-Do

To-Do is operated by one person, not a company. It runs on a privately operated server rather than on a third-party cloud platform. Questions, requests, and complaints go to alecjohnthomas11@gmail.com.

What is collected, and why

Creating an account stores three things about you:

  • Your email address — the one your Apple ID releases to this app. It identifies your account and is shown to the other members of any space you join. No confirmation mail is sent and nothing is currently mailed to you.
  • Your display name — shown next to the items you tick, so a team can see who did what.
  • A colour tint — assigned automatically from a fixed list of six, purely so your initials chip is distinguishable from everyone else’s.

You sign in with your Apple ID, so To-Do never sees, asks for, or stores a password. Apple tells this app only who you are and the email address described above. If you choose Hide My Email, what is stored is the relay address Apple generates, not your real one.

Using the app stores what you type into it:

  • Deals and lists — the title (in practice usually a property address), the client name, whether it is a buyer or seller side, and a closing date.
  • Checklist items — their titles, any notes you add, and due dates.
  • Space names and your own edited copies of the checklist templates.
  • For every item that gets ticked: which account ticked it and the time it happened. This is the point of the app, and the database records it rather than trusting the app to report it.
  • A record of activity within a space — who created, renamed, completed or removed something, and when.
  • Invites — a single-use token, a hash of the four-digit code, who created it, when it expires, whether it was used and by whom, and how many wrong codes were tried.

These fields are free text. Whatever you type goes in exactly as typed, which in normal use means client names and property addresses. Do not put anything in To-Do that you would not want the other members of that space to read.

What is not collected

There is no analytics, no advertising, no tracking pixels, no third-party scripts, and no profiling. Nothing is sold, rented, shared for marketing, or used to train anything. There is no third-party data processor beyond the hosting described below.

Your camera

Joining a space by QR code asks for camera access. The video is read and decoded on your own device to find the code in it. No image, frame, or recording is uploaded or stored, and you can decline and type the invite instead.

What stays on your device

Your sign-in session, which space you had open, and whether you have dismissed the install guide and the first-run walkthrough are kept in your browser’s local storage. Changes made while you are offline are queued in the browser’s database until they can be sent. A copy of the app itself is cached so it opens without a signal. Signing out clears the session; clearing the site’s data in your browser clears the rest.

Who can see your data

Everyone in a space can see and change everything in it — every deal, every list, every item, and every completion. They can also see the display name, email address, and colour of everyone else in that space. Someone who is not in your space cannot read any of it: access is enforced by row-level security in the database itself, not by the app, so it holds even against a request made directly to the database’s own API.

The person who operates the server has administrative access to it and therefore to the database. That is stated plainly because it is true of any self-hosted service and is not something a policy can promise away.

Where it is stored

On a privately operated server, in a PostgreSQL database. Traffic between your device and that server is carried over HTTPS through a network tunnel provider, which relays the connection. Data is not separately encrypted at rest — treat the database as readable by anyone with physical or administrative access to the machine.

A compressed backup of the database is taken nightly and kept for fourteen days, so anything deleted may still exist in a backup for up to two weeks after it disappears from the app.

To-Do is a small, privately run service. It does not claim certification or formal compliance under GDPR, CCPA, SOC 2, or any similar framework, and this page should not be read as making that claim.

How long it is kept, and how to delete it

Everything is kept for as long as your account exists. There is no self-serve delete button today — this is worth being blunt about rather than implying a control that is not there. To have your account removed, email alecjohnthomas11@gmail.com from the address on the account.

Deleting your account deletes your profile — your email address, display name, and colour — and removes you from every space. It does not delete the deals, lists, and checklist items you created in a shared space: those belong to the space and stay visible to its other members, with your name detached from them. If you want that content gone as well, say so in the same email and be specific about which space.

You can change your display name yourself at any time under Settings. To get a copy of what is stored about you, ask at the same address.

Children

To-Do is a tool for working real-estate agents and is not directed at children. It is not for anyone under 13, and accounts belonging to anyone under 13 will be deleted.

Changes to this policy

If what the app stores changes, this page changes with it and the date at the top moves. Continuing to use To-Do after a change means you accept the updated policy.

Contact

alecjohnthomas11@gmail.com — for deletion requests, data requests, and anything else about this page. See also the Terms of Service.